PT-2021-11959 · Unknown · Rails Admin

Mshibuya

·

Published

2021-01-12

·

Updated

2021-01-14

·

CVE-2020-36190

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: RailsAdmin versions prior to 1.4.3 RailsAdmin versions 2.x prior to 2.0.2
Description: The issue allows for XSS via nested forms, which can lead to malicious script execution.
Recommendations: For versions prior to 1.4.3, update to version 1.4.3 or later. For versions 2.x prior to 2.0.2, update to version 2.0.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36190
GHSA-WJX2-7HQQ-8H7M

Affected Products

Rails Admin